AI governance for engineering teams

Regels in de repo. Geen commissie.

Your team already uses AI. Without rules, that’s a liability. I fix that.

Shadow tools. Secrets in prompts. Seniors who refuse the seats, and juniors who ship whatever the model wrote. I take ownership of the rules, the gates, and the habit of shipping — until the whole team can run it without me.

Fair warning: I don’t wait for six meetings and a committee decision. If you need someone who colors inside a strategy deck, I’m not your guy.

noctis — readiness

shadow_ai
found
secrets
in prompts
policy
a slide, not a gate
seniors
split
shipping
uneven
owner
unassigned

I take the owner field.

The work

Shadow AI, then gates, then the whole team ships.

Not a workshop series. Three things I own, in order.

01 — Shadow AI

Find it before it ships.

Unmanaged AI across tools, workflows, and vendors. Copied production data. Rogue copilots. Quiet refusals from the people you actually need. I surface it before a customer or an auditor does.

02 — Quality gates

Policy the pipeline runs.

Review harnesses and checks that reject AI output which fails your standard. Not a wiki nobody opens. Gates in the repo. If it isn’t enforced, it isn’t a rule.

03 — Whole-team shipping

One standard. Then speed.

Engineers, ops, and security on the same rules — so you ship faster with AI, instead of arguing about the tools. I stay until that is the habit. I don’t hand you a PDF and disappear.

Proof, not a logo wall

When I review your stack, I’m not guessing.

I can open a terminal and prove it. This is the record behind the work. Not client logos I don’t have permission to print. Not metrics invented for a homepage.

  • Still codes

    Most fractional CTOs stopped coding years ago. I didn’t. AI-assisted development, in the repo — not a slide about it.

  • ~250

    Kubernetes nodes. Cloud project leadership on a mobility platform (Mobiliteitsfabriek): multi-cluster, GitOps, Argo CD, Helm, Kyverno, Terraform.

  • 18

    European countries. CTO of a mobile payments platform — Ruby, Elixir, clustering, the unglamorous work of money moving.

  • 2005

    Govannon, established. 27+ years shipping software. Amersfoort. English and Dutch.

  • Readiness

    SOC 2, ISO 27001, GDPR, HIPAA readiness. Controls in the platform. I will not print a certificate I did not earn.

  • Libraries

    Open-source Elixir other teams run: cloudex, set_locale, ecto_translate. Shared tools, not demos. github.com/smeevil

Most fractional CTOs stopped coding years ago. I didn’t.

The path here: Windows server parks at Heineken, then the Netherlands’ first crowdfunding stack with ABN AMRO — pen testing, payments, coaching their team. Then payments at country scale, then Kubernetes at fleet scale. Same person. Still shipping. Code Noctis is that instinct aimed at how your engineering team uses AI. Operated by Govannon.

The call

A readiness call. Not a pitch deck.

Outcomes, not deliverables. Not experimenting. Shipping.

What happens

  1. I ask what your team already pasted into which tools.
  2. I tell you where that is a liability. If I can’t help, I say so.
  3. Gates go in the repo. Policy the pipeline actually runs.
  4. I stay until the team ships under the rules. Then I leave.

What you don’t get

  • A 40-page AI strategy.
  • A junior bench wearing my name.
  • Six workshops to align stakeholders.
  • Someone who waits for a committee.

Contact

Gerard de Brieder

Code Noctis is operated by Govannon. Same person who answers the phone.

+31 6 2496 3568

info@govannon.nl

linkedin.com/in/smeevil

Amersfoort, Netherlands. I overlap US hours.